Template Support for Yealink T4x SIP over TLS & SRTP using Remote STUN

Status
Not open for further replies.

ltctech

Silver Partner
Joined
Sep 13, 2019
Messages
40
Reaction score
15
Due to COVID-19 many of our employees are working from their home offices where it'd be impractical to deploy an SBC. The best solution is "Direct SIP (STUN Remote)". The catch is that all SIP signaling and RTP audio is sent in the clear for anyone to intercept.

It's trivial to create a custom template for Yealink T4x that sets the phone to use SIP over TLS (SIPS) and SRTP. What I would really like is built-in template support.

I have attached my custom template to this post if anyone is interested in using it. All non-cosmetic changes are commented with "SecureMod". The template uses a y-file index of 5, make sure you don't have a conflicting template. The template assumes that the phone is being provisioned via RPS and has been reset to factory defaults.

Read this before using it:
https://www.3cx.com/docs/custom-ip-phone-templates/

Your 3CX server should already be TLS enabled with a valid certificate signed by a public CA e.g. Let's Encrypt.

You will need to enable SRTP under "3CX App" provisioning for the extension, "Normal" RTP Mode will cause call failure:

RTP Mode: "Only Secure" or "Allow Secure"

IMO, the best settings to use under "3CX App" extension provisioning:
SIP Transport: TLS
RTP Mode: "Only Secure"
Unchecked "Use 3CX Tunnel for remote connections (3CX App only)"
Under extension options: Unchecked "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"

I have tested the custom template with a Yealink SIP-T46S and a SIP-T48S. You may have to factory reset the phone to clear out the settings this custom template modifies. Use at your own risk.
 

Attachments

Trivial for.......someone in the same network... someone who works for the ISP. Outside of that, not so trivial.
 
Just a thought, but if you have a requirement for Secure SIP for your home workers due to high security requirements, etc. Would you not already be required to drop a small but secure firewall in their home already, and thus, 99% of these are IPSEC compliant and you could just pop up a vpn.... And not only knock out the security aspect of the phones, but enable the remote worker to also use in-office files and applications in the same stroke?

Just saying.... Go out into the weeds to Solve 1 problem, or solve all the problem without ever going into the weeds....
 
Just a thought, but if you have a requirement for Secure SIP for your home workers due to high security requirements, etc. Would you not already be required to drop a small but secure firewall in their home already, and thus, 99% of these are IPSEC compliant and you could just pop up a vpn.... And not only knock out the security aspect of the phones, but enable the remote worker to also use in-office files and applications in the same stroke?

Just saying.... Go out into the weeds to Solve 1 problem, or solve all the problem without ever going into the weeds....
Absolutely not. Why would you expose your corporate network to their entire home network, vs just their workstation via a dial-in VPN. Now corp IT is responsible for someone home router, EE's will complain about invasion of privacy, possibility of being watched, and the list goes on.
 
for low end users, paper pushers, sales, etc, your way works, but for anyone high level, have fun with that.

There is this little thing called access control, in which you restrict an ipsec tunnels access, either by a list of IPs, or CIDRs, or both, at both ends, your acting like i intended you to put up a tunnel with /8 and call it good. Client VPNs, or as you refer to them, Dial-in vpns, do not protect your remote worker, just your backend, and if the remote worker downloads for example, WannaCry, or its newer equivalent, guess what that VPN does. It allows the infected PC to pass the infection to your backend just the same.

Not bolstering a remote workers network security, and giving them a VPN of any kind to your backend, is an equal and sometimes bigger risk, big corporations who have remote workers who are critical, will do this, to prevent such.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,283
Members
164,662
Latest member
DejanMDS